linux
Systemd Service Hardening — A Practical Checklist
NoNewPrivileges, PrivateTmp, and CapabilityBoundingSet with real production examples.
Mar 5, 2026
Notes on Linux, networking, and open source. Updated irregularly from somewhere in Europe.
NoNewPrivileges, PrivateTmp, and CapabilityBoundingSet with real production examples.
What each sysctl actually does and how to benchmark.
Automatic HTTPS, simpler config, HTTP/3 out of the box.
Practical migration guide for anyone still on iptables.
Getting intrusion alerts directly to Telegram with a simple webhook action.
Static site. No trackers, no ads. VPS somewhere in Europe.